|
楼主 |
发表于 2009-4-28 14:03:02
|
显示全部楼层
二、病毒运行后的检测。
由于天琊并没有自带启动项目和服务的检测,所以要想快速清理病毒只能配合sreng使用:
01运行样本。
小V病毒:
02样本消失。
过了不久样本消失:
03 出现未知进程。
进程已经出现:
04 很多进程。
未知进程是越来越多:
05 等待病毒运行完全。
我一直在等病毒是否会关闭任务管理器,看来没有这动作:
06 运行天琊。
用天琊看看:
07 运行成功。
运行成功,是最新版本:
08 慎用此操作。
对于天琊的强制删除,要很慎重,此操作不可恢复:
09 结束进程。
一般采用结束进程:
10 记下路径。
由于没有记录功能,所以结束进程前最好手工记下病毒路径:
11 全结束了。
把病毒进程全结束了,排除干扰:
12 用sreng扫描。
sreng扫描挺全面的,用这个弥补一下天琊缺少的启动检测功能:
13 sreng运行正常。
运行很正常看来没挟持SRENG:
14 sreng保存日志。
SRENG异常日志如下,有了这个报告,便可以轻松用天琊除毒了:
日志的大致情况是:基本都是无进程木马,有一个自启动服务,一个驱动加载,大多数是DLL注入型病毒,现在都是流行无进程。
-----------------------------------------------------------------我是分隔线-------------------------------------------------------------------
2009-04-28,01:42:54
System Repair Engineer 2.7.0.1210
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 3 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
进程特权扫描
计划任务
API HOOK
隐藏进程
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RsTray><C:\WINDOWS\system32\scvhost.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><C:\WINDOWS\System32\12days.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{669029EE-81FB-496F-9AC4-FE838B16F231}><C:\WINDOWS\system32\erdznUfbK0ZF.dll> []
<{4E5CFE74-700B-4A8B-B0BF-A6B47D896C18}><C:\WINDOWS\system32\GrTZqH5SnRhAt.dll> []
<{56BC86C7-0692-4F94-A2C1-6CF1DBF8096C}><C:\WINDOWS\system32\56BC86C7.dll> []
<{028A997C-4262-4107-BD46-2ABBC6143E8C}><C:\WINDOWS\system32\efc0c52cc1.dll> []
<{AA4CD878-B510-4508-83EB-DE968E358D15}><C:\WINDOWS\system32\Nj4gYd3rUbJ57.dll> []
<{08223B03-1B38-4A33-A83A-A4D3CC1D6E4E}><C:\WINDOWS\system32\08223B03.dll> []
<{7A93621D-BFFE-4EB1-AAE1-CD487F429840}><C:\WINDOWS\system32\PkVyCX5kHnftC7BXjt.dll> []
<{FBFAD3A6-0B1E-4122-9C2B-92A4623875EC}><C:\WINDOWS\system32\v6yj3gxacYQU.dll> []
<{A23CA53C-731F-4033-92E8-C1DFB4E71D34}><C:\WINDOWS\system32\JBn2ypqY23vWX.dll> []
<{704C3595-DB85-40F6-A601-8D6F346907BD}><C:\WINDOWS\system32\704C3595.dll> []
<{122B901E-493F-4AD9-BC69-7DE8C3E52FCC}><C:\WINDOWS\system32\122B901E.dll> []
<{16E42559-9ED5-46FD-878E-DC5D42746BB5}><C:\WINDOWS\system32\peV7mS4gcukR.dll> []
<{76B9BA7A-81D0-4979-8598-8471F2AB5186}><C:\WINDOWS\system32\76B9BA7A.dll> []
<{0D267113-499A-4EEF-998D-C45731C1B313}><C:\WINDOWS\system32\VnTU2WAqUcZA6.dll> []
<{93DA1E7D-7C46-4F90-8674-EC90511FCA72}><C:\WINDOWS\system32\CDuAUVkGy9.dll> []
<{CCCA2FB9-2D5D-4481-8BFE-1CDDC458A3F4}><C:\WINDOWS\system32\CCCA2FB9.dll> []
<{36AC68E6-0C26-4D39-B98E-54B49DAB6BAA}><C:\WINDOWS\system32\dhDhwS7fFW.dll> []
<{737858A9-9AEA-4838-9B49-54DA731F7F37}><C:\WINDOWS\system32\BMsg6pdMD4ht.dll> []
<{2EF0D734-21FD-4225-A1A2-BCD296182AAF}><C:\WINDOWS\system32\2EF0D734.dll> []
<{C722AD57-35DA-4460-8353-328372F32AB2}><C:\WINDOWS\system32\ufQCU5.dll> []
<{A5CA6C70-7185-4466-AB45-B1C34E7A37CA}><C:\WINDOWS\system32\ed78ab9.dll> []
<{E4814792-EFA3-4C20-93D0-8B130A59F9A8}><C:\WINDOWS\system32\E4814792.dll> []
<{A1A6BC2E-C6A1-43C1-8884-A31D772F42B8}><C:\WINDOWS\system32\A1A6BC2E.dll> []
<{171565E3-F0BB-4FF0-9A42-C9406C79DB78}><C:\WINDOWS\system32\wF87W8XjgDW5Es6tuA.dll> []
==================================
启动文件夹
N/A
==================================
服务
[szace / szace][Stopped/Auto Start]
<C:\WINDOWS\system32\szace.exe><N/A>
==================================
驱动程序
[mtlrd / mtlrd][Running/Auto Start]
<\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Media Player\wmp\mtlrd.sys><N/A>
==================================
浏览器加载项
==================================
正在运行的进程
[PID: 1724 / tawny01][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\SysDir.dat] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\elementzx.dll] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\jxinit.dat] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\xccs.dll] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\elementwlwz.dll] [N/A, ]
[C:\WINDOWS\system32\erdznUfbK0ZF.dll] [N/A, ]
[C:\WINDOWS\system32\GrTZqH5SnRhAt.dll] [N/A, ]
[C:\WINDOWS\system32\56BC86C7.dll] [N/A, ]
[C:\WINDOWS\system32\efc0c52cc1.dll] [N/A, ]
[C:\WINDOWS\system32\08223B03.dll] [N/A, ]
[C:\WINDOWS\system32\PkVyCX5kHnftC7BXjt.dll] [N/A, ]
[C:\WINDOWS\system32\v6yj3gxacYQU.dll] [N/A, ]
[C:\WINDOWS\system32\JBn2ypqY23vWX.dll] [N/A, ]
[C:\WINDOWS\system32\704C3595.dll] [N/A, ]
[C:\WINDOWS\system32\122B901E.dll] [N/A, ]
[C:\WINDOWS\system32\peV7mS4gcukR.dll] [N/A, ]
[C:\WINDOWS\system32\76B9BA7A.dll] [N/A, ]
[C:\WINDOWS\system32\VnTU2WAqUcZA6.dll] [N/A, ]
[C:\WINDOWS\system32\CDuAUVkGy9.dll] [N/A, ]
[C:\WINDOWS\system32\CCCA2FB9.dll] [N/A, ]
[C:\WINDOWS\system32\dhDhwS7fFW.dll] [N/A, ]
[C:\WINDOWS\system32\BMsg6pdMD4ht.dll] [N/A, ]
[C:\WINDOWS\system32\2EF0D734.dll] [N/A, ]
[C:\WINDOWS\system32\ufQCU5.dll] [N/A, ]
[C:\WINDOWS\system32\ed78ab9.dll] [N/A, ]
[C:\WINDOWS\system32\E4814792.dll] [N/A, ]
[C:\WINDOWS\system32\A1A6BC2E.dll] [N/A, ]
[C:\WINDOWS\system32\wF87W8XjgDW5Es6tuA.dll] [N/A, ]
[C:\WINDOWS\system32\dopdy.dll] [, 4.4.2.0]
[C:\WINDOWS\system32\mtlrd.dll] [, 4.4.2.0]
[C:\WINDOWS\system32\Nj4gYd3rUbJ57.dll] [N/A, ]
[PID: 1928 / tawny01][C:\Program Files\VMware\VMware Tools\VMwareTray.exe] [VMware, Inc., 6.0.0 build-45731]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\SysDir.dat] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\elementzx.dll] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\xccs.dll] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\jxinit.dat] [N/A, ]
[C:\WINDOWS\system32\erdznUfbK0ZF.dll] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\elementwlwz.dll] [N/A, ]
[C:\WINDOWS\system32\56BC86C7.dll] [N/A, ]
[C:\WINDOWS\system32\efc0c52cc1.dll] [N/A, ]
[C:\WINDOWS\system32\08223B03.dll] [N/A, ]
[C:\WINDOWS\system32\PkVyCX5kHnftC7BXjt.dll] [N/A, ]
[C:\WINDOWS\system32\JBn2ypqY23vWX.dll] [N/A, ]
[C:\WINDOWS\system32\v6yj3gxacYQU.dll] [N/A, ]
[C:\WINDOWS\system32\704C3595.dll] [N/A, ]
[C:\WINDOWS\system32\peV7mS4gcukR.dll] [N/A, ]
[C:\WINDOWS\system32\76B9BA7A.dll] [N/A, ]
[C:\WINDOWS\system32\CCCA2FB9.dll] [N/A, ]
[C:\WINDOWS\system32\BMsg6pdMD4ht.dll] [N/A, ]
[C:\WINDOWS\system32\2EF0D734.dll] [N/A, ]
[C:\WINDOWS\system32\A1A6BC2E.dll] [N/A, ]
[PID: 1672 / tawny01][C:\Program Files\VMware\VMware Tools\VMwareUser.exe] [VMware, Inc., 6.0.0 build-45731]
[C:\WINDOWS\system32\A1A6BC2E.dll] [N/A, ]
[C:\WINDOWS\system32\2EF0D734.dll] [N/A, ]
[C:\WINDOWS\system32\BMsg6pdMD4ht.dll] [N/A, ]
[C:\WINDOWS\system32\CCCA2FB9.dll] [N/A, ]
[C:\WINDOWS\system32\76B9BA7A.dll] [N/A, ]
[C:\WINDOWS\system32\peV7mS4gcukR.dll] [N/A, ]
[C:\WINDOWS\system32\704C3595.dll] [N/A, ]
[C:\WINDOWS\system32\JBn2ypqY23vWX.dll] [N/A, ]
[C:\WINDOWS\system32\v6yj3gxacYQU.dll] [N/A, ]
[C:\WINDOWS\system32\PkVyCX5kHnftC7BXjt.dll] [N/A, ]
[C:\WINDOWS\system32\08223B03.dll] [N/A, ]
[C:\WINDOWS\system32\efc0c52cc1.dll] [N/A, ]
[C:\WINDOWS\system32\56BC86C7.dll] [N/A, ]
[C:\WINDOWS\system32\erdznUfbK0ZF.dll] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\elementwlwz.dll] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\xccs.dll] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\jxinit.dat] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\elementzx.dll] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\SysDir.dat] [N/A, ]
[C:\WINDOWS\system32\mtlrd.dll] [, 4.4.2.0]
[C:\WINDOWS\system32\dopdy.dll] [, 4.4.2.0]
[C:\WINDOWS\system32\Nj4gYd3rUbJ57.dll] [N/A, ]
[PID: 2012 / tawny01][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\SysDir.dat] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\elementzx.dll] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\jxinit.dat] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\xccs.dll] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\elementwlwz.dll] [N/A, ]
[C:\WINDOWS\system32\erdznUfbK0ZF.dll] [N/A, ]
[C:\WINDOWS\system32\56BC86C7.dll] [N/A, ]
[C:\WINDOWS\system32\efc0c52cc1.dll] [N/A, ]
[C:\WINDOWS\system32\08223B03.dll] [N/A, ]
[C:\WINDOWS\system32\PkVyCX5kHnftC7BXjt.dll] [N/A, ]
[C:\WINDOWS\system32\v6yj3gxacYQU.dll] [N/A, ]
[C:\WINDOWS\system32\JBn2ypqY23vWX.dll] [N/A, ]
[C:\WINDOWS\system32\704C3595.dll] [N/A, ]
[C:\WINDOWS\system32\peV7mS4gcukR.dll] [N/A, ]
[C:\WINDOWS\system32\76B9BA7A.dll] [N/A, ]
[C:\WINDOWS\system32\CCCA2FB9.dll] [N/A, ]
[C:\WINDOWS\system32\BMsg6pdMD4ht.dll] [N/A, ]
[C:\WINDOWS\system32\2EF0D734.dll] [N/A, ]
[C:\WINDOWS\system32\A1A6BC2E.dll] [N/A, ]
[PID: 1680 / tawny01][C:\WINDOWS\system32\conime.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\dopdy.dll] [, 4.4.2.0]
[C:\WINDOWS\system32\mtlrd.dll] [, 4.4.2.0]
[C:\WINDOWS\system32\A1A6BC2E.dll] [N/A, ]
[C:\WINDOWS\system32\2EF0D734.dll] [N/A, ]
[C:\WINDOWS\system32\BMsg6pdMD4ht.dll] [N/A, ]
[C:\WINDOWS\system32\CCCA2FB9.dll] [N/A, ]
[C:\WINDOWS\system32\76B9BA7A.dll] [N/A, ]
[C:\WINDOWS\system32\peV7mS4gcukR.dll] [N/A, ]
[C:\WINDOWS\system32\704C3595.dll] [N/A, ]
[C:\WINDOWS\system32\JBn2ypqY23vWX.dll] [N/A, ]
[C:\WINDOWS\system32\v6yj3gxacYQU.dll] [N/A, ]
[C:\WINDOWS\system32\PkVyCX5kHnftC7BXjt.dll] [N/A, ]
[C:\WINDOWS\system32\08223B03.dll] [N/A, ]
[C:\WINDOWS\system32\efc0c52cc1.dll] [N/A, ]
[C:\WINDOWS\system32\56BC86C7.dll] [N/A, ]
[C:\WINDOWS\system32\erdznUfbK0ZF.dll] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\elementwlwz.dll] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\xccs.dll] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\jxinit.dat] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\elementzx.dll] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\SysDir.dat] [N/A, ]
[PID: 636 / tawny01][C:\sreng2\SRE5adef2a7.EXE] [Smallfrogs Studio, 2.7.0.1210]
[C:\WINDOWS\system32\mtlrd.dll] [, 4.4.2.0]
[C:\WINDOWS\system32\dopdy.dll] [, 4.4.2.0]
[C:\WINDOWS\system32\A1A6BC2E.dll] [N/A, ]
[C:\WINDOWS\system32\2EF0D734.dll] [N/A, ]
[C:\WINDOWS\system32\BMsg6pdMD4ht.dll] [N/A, ]
[C:\WINDOWS\system32\CCCA2FB9.dll] [N/A, ]
[C:\WINDOWS\system32\76B9BA7A.dll] [N/A, ]
[C:\WINDOWS\system32\peV7mS4gcukR.dll] [N/A, ]
[C:\WINDOWS\system32\704C3595.dll] [N/A, ]
[C:\WINDOWS\system32\JBn2ypqY23vWX.dll] [N/A, ]
[C:\WINDOWS\system32\v6yj3gxacYQU.dll] [N/A, ]
[C:\WINDOWS\system32\PkVyCX5kHnftC7BXjt.dll] [N/A, ]
[C:\WINDOWS\system32\08223B03.dll] [N/A, ]
[C:\WINDOWS\system32\efc0c52cc1.dll] [N/A, ]
[C:\WINDOWS\system32\56BC86C7.dll] [N/A, ]
[C:\WINDOWS\system32\erdznUfbK0ZF.dll] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\elementwlwz.dll] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\xccs.dll] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\jxinit.dat] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\elementzx.dll] [N/A, ]
[C:\DOCUME~1\TAWNY0~1.200\LOCALS~1\Temp\SysDir.dat] [N/A, ]
[C:\WINDOWS\system32\Nj4gYd3rUbJ57.dll] [N/A, ]
==================================
文件关联
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
==================================
计划任务
N/A
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
-------------------------------------------------------------------我是分隔线------------------------------------------------------------------
附:原日志和筛选后的日志
[ 本帖最后由 tawny2008 于 2009-4-28 18:17 编辑 ] |
评分
-
查看全部评分
|